#cyber-and-careers

1 messages · Page 56 of 1

hallow sinew
#

Ethical Hacking has aged me more than programming ever did.

indigo stream
#

just been working in C#, Android mostly. Why do you stay in ethical hacking if I may ask?

hallow sinew
#

Greater challenge

indigo stream
hallow sinew
#

It varies

hollow falcon
#

I got 1 hour till I take off for my interview.

What questions should I be prepared for when interviewing for a cybersec analyst position?

And what can I say that could "Wow!" them?

#

I asked chatgpt the typical day of a cybersec analyst and went from there to get a better grip of the game

crude burrow
#

How you work in a group.
Hobbies, interests that might relate to the role.
Talk about looking to get Microsoft Certs focued towards SOC

hollow phoenix
#

Hey man, sorry for the lack of follow-up there.

I did the research and found out that job listings are asking for certs way less that I imagined, but the ones that did were asking for different stuff, so while the picture is clearer, it has many different colors

crude burrow
#

you should probably htougt about this a few days ago.

Just lean a bit foward, be confident. talk about something that you know. Do not lie and wing things. When asked questions draw paralells or refer to things in real ife that you know and can be confident about

crude burrow
#

Just have a genuine interest and somewhat knowlage about the topic ahead. They will teach you everything you need too know

hollow phoenix
#

Yeah, thats one of the points I concluded on after my research. In fact, university/college degree are still way far more demanded than certs

#

That's not to say all or almost all job offerings were asking for it, ofc

crude burrow
#

I would dox the company as much as I can.

Big company = lots of vhosts(subs). I would look at shodan and find services that contain the companys name in their subs.

FIgure out what they run and get some small knowlage about what it is and mention I look forward to learn about it etc

#

But that is me and I am broken. I dox everyone and everything

#

Osint is fun 🙂

hollow phoenix
#

Not a bad way to go about it. A very red team method as well

crude burrow
#

When I was asked about salary I already knew everyones salary in the meeting. 😄

hollow phoenix
# crude burrow Osint is fun 🙂

It's interesting. Always feels good to think you know more about others than they know about you, better yet it being actually true

hollow falcon
crude burrow
#

As long as one do not lie

hollow falcon
#

Idk if I should bring it up

hollow phoenix
#

Already did

crude burrow
#

I just got a kid fired from his job and the next one he applied too. He was interviewing in my team.

I recognised his name. Thougt about it for two weeks. Asked courts for his papers and got them during intervjew. Lucky for him he was remote and not face to face

#

He would have tripped down the stairs

hollow phoenix
#

Court?

hollow falcon
#

Im not gpnna lie lol.

Its just, mainly my cybersec experience is offensive not defense

crude burrow
#

he was concited of sexual exposure of minors.

hollow phoenix
#

Oof

hollow falcon
#

Gross

crude burrow
#

Those papers are public knowlage here

hollow phoenix
#

US?

crude burrow
#

He was currently hired at one if the biggest security firms in the world, got let go.

Got hired at an even bigger firm, I got him fired within 5 days 🙂

hollow falcon
#

Wow

hollow phoenix
#

Chasing preds

hollow falcon
#

Quite the story lol

hollow phoenix
#

Damn

crude burrow
#

And if he is dumb enough to post his new job (if he ever gets one) on linked in. I am back at it

hollow falcon
#

I swwar I better not mess up

#

Been studying non stop

crude burrow
# hollow falcon I swwar I better not mess up

Interviews come and go, Just be positive and show a will to learn. They do not expect you to know everything.

Just have a wast idea of what cyber security analyst is.

I work as a SOC, I use multiply log sources, We work alot in Microsoft Entra and Defender etc.

It is not rocket science

#

I can teach anyone to do it

hollow falcon
crude burrow
#

If they use XSIAM or Cortex etc. I will teach you after work 😄

hollow phoenix
crude burrow
#

Phishing with pdfs with QR codes are super huge right now

#

They bypass all checks in defender

crude burrow
#

Thats it in a nutshell.

hollow phoenix
#

I've done some triaging, packet capture and analysis, escalation, malware analysis, case follow-up, and very superficial SIEM and IDS messing around

hollow falcon
#

Also playbooks and firewall configs

crude burrow
#

Playbooks are great

hollow phoenix
#

I'd like to be able to do more with the SOC sim but it's just for businesses

hollow falcon
#

I wish I could review Splunk or OpenVAS, wasnt the latter free at one point? I remember messing with it back in late 2021

crude burrow
#

I would ask how they were effected by Salesforce breach, Oracle cloud before the summer, etc

#

Those were quite big breaches

hollow falcon
#

They got hacked in 2023 I remeber that. The super intendent quit cause of it

crude burrow
#

Sharepoint recently also.

#

Depends on the company 😄

#

(you see that I like babbling, so I can do the interview with myself)

#

Just trying to help

hollow falcon
#

Its ok i appreciate it

#

Cause I habe 30 mins left lol

#

Have*

crude burrow
#

I hope you get a second interview

hollow falcon
#

It should be one from what I know

hollow phoenix
#

Best if luck

hollow falcon
#

Hopefullly

crude burrow
#

I had 3.

#

for 1 position

#

Manager & HR

hollow falcon
#

Ive been there

crude burrow
#

Manager & Team
Grandpa interviews last

hollow falcon
#

Yup

#

The vips

crude burrow
#

I just talked about my homelab for 30 min and my 3d printers and hacking in general

hollow falcon
#

Thats the thing, I have to not get anxiety stupid and mix my ethical hacking with my greyhat exp days

#

By ethical I mean THM lol

crude burrow
#

Be proud about greyhat

#

That is what gives you validity

hollow falcon
#

I just dont want to get in trouble or denied cause of it. Some employers will mark you for it

crude burrow
#

Kids today just want to pentest and have no clue what it was growing up with dail-up modems

hollow falcon
#

I remeber when WiFi router were wap or had no security configuration

crude burrow
#

haha WEP

#

Like locking your bike with thread

hollow falcon
#

Pretty much

crude burrow
#

pofh and open

#

WEP was the worst ever

#

couple of hand shakes and open sesamy

hollow falcon
#

Use to steal my niegbors internet lol

crude burrow
#

Let us know how it went after

hollow falcon
#

Downloaded GTA san Andreas on the 360 lol

hollow falcon
hollow phoenix
#

Ace it

#

One thing that I did feel kind of insecure about, was that a lot of job offerings asked for uni/college degrees, and I don't have one

obsidian rose
#

Don't post links to files for download please.

chrome spire
#

Needa see at least 4

hollow falcon
#

I think I did good but not perfect

#

And they probably wanted perfect

#

But, well see idk

#

They seemed impressed. They gave me 13x questions

#

4x people

#

What I felt kept marking me was the questions related to security defense experience.

Which I dont have so I had to substitute with other similar examples I have done

#

I mean, I have done basic stuff like virus removal and analysis of accounts for compromise

#

Also, I totally forgot to mention my medium articles x.x

That could have been the deal breaker

crude burrow
#

Are they in your name?

#

the articles, if so they might have seen them already

hollow falcon
#

Only if they saw my linkedin which I doubt.

They do know about my two certs!

hollow falcon
#

This the latest I made

#

My offensive havking skills would NOT have impressed them. Trust me, I was really in a corner

#

I still think I did good

#

Especially for a greenhorn

#

Cyber defense wise

crude burrow
#

Great posts but Ima make fun of you in the future 😄

hollow falcon
hollow falcon
crude burrow
#

Nono nothing like that

viscid vigil
#

Guys, can someone tell me how I can buy a subscription to TryHackMe because it's throwing various errors. What is the solution? Anyone can guide

crude burrow
#

@viscid vigil What are the errors

#

you select what kind of sub you want, enter your info and add your card

tidal island
#

Can you suggest me which language, I will start first for cybersecurity. I have zero knowledge on programming.

viscid vigil
#

declined transaction exceeded limit

#

A number of recent transactions on this card have been declined. Please wait before you try again, or use a different payment method.

zealous solstice
#

Reverse Engineering

tacit karma
crude burrow
#

Try use your own card

#

Sounds like carding

warm hinge
flat sedge
north bridge
#

Anyone here professional cybersecurity expert or anyone who can help who doing work in any organization from India.
I need a small help is there any opening can you please refer me .
It would be very grateful is anyone would help me.

crude burrow
#

He's merchant is refusing the transfer due to reasonsm nothing THM can do

#

@north bridge Old enough to have a proper job?

north bridge
#

yup i am 22 graduated

#

btech cs

crude burrow
#

TCS did not work out for you?

north bridge
#

na actually graduated in 2024 and that time i didn't fill form and now whenever i filling the form there is no response

#

from tcs

crude burrow
#

Phone them

north bridge
crude burrow
#

Tell them you are reado for work

tacit karma
crude burrow
#

unpaid job = never ever accept

north bridge
crude burrow
#

So you want a foot in cybresecurity. What big global firms have you thougt about contacting?

#

TCS is a shtty place, but a job is a job. And it is easier to get a new job if you are employed already.

tacit karma
#

plus udemy was free for a month or something

crude burrow
#

Let me see what I can find. Just wrapping up late lunch

warm hinge
#

ah my uni paid for that one

north bridge
tacit karma
warm hinge
crude burrow
#

I have some contacts at TCS via work

tacit karma
#

whats a tempmail

warm hinge
crude burrow
#

But they pay crap and I would never work there

north bridge
tacit karma
warm hinge
# tacit karma whats a tempmail

“A temporary email address is generated for you instantly and self-destructs after a short period, automatically deleting all received messages. This allows you to sign up for services, receive verification links, and avoid spam without needing to set up a password or log in, keeping your main inbox clean and protecting your privacy. “

north bridge
tacit karma
#

but the courses for like python come from universities here too

crude burrow
#

you need to start somewhere

warm hinge
crude burrow
#

Cant expect to get a dream job 1st time

north bridge
crude burrow
#

Why would a start up need a jr

north bridge
crude burrow
#

JRs need seniors too teach them

north bridge
warm hinge
#

i joined the cybersecurity course on coursera and the only new things i learned were names and fancy terms

#

codingwise youtube is better

north bridge
crude burrow
#

I would prepare my CV, make sure you get rid of the indian english, becasue that is hard to worh with tbh.

tacit karma
crude burrow
#

Accent is not the issue, its the flow. You know what I am talking about

crude burrow
#

It is an never ending row of words

tacit karma
#

right now rust

#

but i took a few from pearson, the people who do the a+ cert and such. the comptia ones

warm hinge
warm hinge
#

how u cover the fees

tacit karma
#

coursera plus is monthly, if you learn faster than expected you can get these low level certs in under a month

crude burrow
#

I encounter this multiply times per day

warm hinge
crude burrow
#

Goa, Deli,Banglor etc all have the same structure

warm hinge
#

anyway the indian code youtube never worked for me

crude burrow
#

It is not the accent, its they way they talk. It is not western english

warm hinge
#

they r good for science technical stuff that u cant figure out

#

wait what u tryna do again

crude burrow
#

@warm hinge Where are you from?

warm hinge
#

some asian country im not proud of but not being protested

crude burrow
#

Are you trying to discuss indian english based on what you have seen/heard on youtube?

warm hinge
crude burrow
#

I am just trying to help the guys get a job.

north bridge
#

chill guys ..

warm hinge
#

right i just scrolled up

crude burrow
#

And if they learn to structure their English, it will be easier to land a job outside India or working as a consultant towards companies outside india

warm hinge
#

we r chill

crude burrow
#

@north bridge It is all good, the dude made my day

north bridge
#

i mean to say not to argue on this .. blobfingerguns

crude burrow
#

Arguing based of youtubers

warm hinge
crude burrow
#

Oh

warm hinge
crude burrow
#

You think there are too many Indians?

warm hinge
#

fuck i cant send image

warm hinge
north bridge
#

wdu think is pt1 certification is better or htb certification ?

crude burrow
#

I would not say any of them

north bridge
#

ic

crude burrow
#

What do you want to do?

north bridge
#

vapt

crude burrow
#

So that can be two diffrent paths

north bridge
#

ahh two diff paths?

#

wdym?

crude burrow
#

VA can be done as a SOC Analyst of any kind.

#

Easier to start with and then merge in to the Pentest part

north bridge
#

yeah .. i got it

#

So like i have to start with SOC l1

crude burrow
#

Ans doing Vulnerability analysing can also be validating/triaging

#

There you have the pentest part

north bridge
#

ahh you mean vdp or bug bounty

crude burrow
#

It is one thing that Pentera, or any system alerts. "CVE XXX"
But then you need to prove it

north bridge
#

got it bro thx

north bridge
flat sedge
warm hinge
#

question (decision-related):

I’m about to enter my third year of whatever computer related degree it is but I have an offer for at least one year contract to make AI at certain company. I know it seems like a bad idea to the traditional system, but is it that bad if i took a pause in my study then come back to study after i finish my one year contract? It’s something I enjoy doing and I thought it would be nice to take a pause from constantly learning way too many things and do what I want

fringe spade
#

Maybe there are some other options, like continuing the degree part time?

warm hinge
warm hinge
fringe spade
warm hinge
#

and the lecturers gotta pick kids up and dont wanna bother them over the weekends

obsidian rose
#

Bump.

junior cliff
#

Is a degree actually required to make it in cyber security and am I cooked if I Carnt get a degree

warm hinge
junior cliff
fringe spade
warm hinge
junior cliff
warm hinge
junior cliff
#

Online lol it was for 8 weeks

warm hinge
#

the one i mention is the one like an intern. they pay during your bootcamp and after finish u just kinda work in big places

junior cliff
#

Type thing

#

Thing is I can’t even afford certs rn …Ik embarrassing

warm hinge
junior cliff
warm hinge
slow tundra
#

anyone got to do the Penetration tester path from scratch with t he app and found a job?

junior cliff
#

Yes that’s what I’m trying to do the market is cooked down England lol even for helpdesk lol

#

Trynna find them is not easy

junior cliff
#

Thanks for the advice can we connect ? Seen as u from here to

serene umbraBOT
#

Gave +1 Rep to @mint ridge (current: #3162 - 1)

mint ridge
#

sure

vernal lark
#

Hi everyone! 👋

I'm currently working as an IT Desktop Support Engineer at a software company on the infrastructure team, lost of compliance. SOC, ISO & PCI DSS to name a few. Because of this my day-to-day can look like lots of checklists and change requests.

When my work does get technical it looks like the below:
||Mostly L1, occasionally L2 support tickets, patch management using PDQ, managing Windows Terminal Server environments, remediation of vulnerabilities found by Nessus, Active Directory user accounts, DNS/DHCP, and some PowerShell scripting (often AI-assisted or adapted from articles).||

I'm actively learning Python and working through a back end web development course via boot.dev, and I’m really enjoying the scripting / programming side of things. I’d like to strengthen my Python skills further and brush up on networking fundamentals — I’d say I’m “okay” at networking but not deeply confident yet, I've done some complex networking with pfSense, managed switch and basic SDN with proxmox for home lab.

I’m a little lost as to where to go from here and want to start exploring career paths and certifications and would love advice on the best route forward.

I've been interested in Cyber security / ethical hacking and pen testing for a while but I've also been liking staring at a screen of code trying to problem solve that. So web development does sound like a possibility too.

As far as certifications and career goes:

  • Should I pursue Cisco CCNA before going for OSCP or other security-focused certs?
  • Is it better to aim for a SOC Analyst role first (after CCNA and become proficient in Python), perhaps while I study OSCP?
  • Are there other certs or learning paths you’d recommend based on my current experience and interests?

I’m also here to connect and learn from others, so if you’ve made a similar transition or have insights, I’d really appreciate hearing your story!

Thanks in advance 🙏

spice plover
#

Good morning, I am currently an IT System analyst for a large company how do I transition to cyber? I will probably have to go to another company

pseudo kettle
#

How's the job market going with everyone so far ?

crude pollen
#

Anyone know legit companys that will pay someone to learn certs from scratch?
Zero prior exp

#

.

crude pollen
undone shore
#

Internships are usually given to people on relevant degree programmes, or who otherwise already have some prior attestation to their ability.

They also don't cost the company much (if anything, company dependent), unlike certs which can cost thousands.

#

You're asking for-profit organisations to invest in you. What do they get in return?

crude pollen
flat sedge
undone shore
# crude pollen There's a lot of mixed info in my research still. That this career is very under...

Remember that an "entry level pentester" (for example), traditionally would still have a lot of experience (think, years) in another IT role.

When they say there are lots of roles, that's generally who they're looking for to fill them.
That's also not really the case now -- a lot of companies have had big redundancy sweeps in the last year or two, so there are lots of folk with prior experience looking for jobs.

crude pollen
#

Okay, thank you both

#

And as for ,,, is it worth it then given I would be starting from scratch, and then competing against thousands who have lots more experience, certs and degrees?
I say this as a person with disabilities, so, up and finding another career comes with a lot of barriers.
So if I can make it work, train myself, is there a general agreement in people getting paid work?

#

.
So far I have Redditors that have said yes, but then a glaring amount of people point out that it sounded very saturated, with talented and experienced people.

static tide
#

You could look into apprenticeships if you are UK based

crude pollen
#

Canadian, sadly

rigid isle
balmy dove
#

do you have local OWASP/security clubs you can particpate in

patent current
#

Hi guys, I am looking to move my career from sales into cyber security - is there learn on the job roles? Or better to study while i currently work in sales until I get X qualification?

crude pollen
#

Valid points, I appreciate it

crude pollen
lilac cargo
#

Hi guys u am recently working on soc2 compliance report anyone able to help?

coral token
#

Hey y'all, in the midst of a carer change from banking advisor/sales to cyber security. Here is my Profile/Summary and skills. I'm not sure if the tools I listed are under the right headings so any advice would be appreciated.

obsidian rose
#

@undone shore Hello. 👋🏼
I think you'll have the answer to my question. Are you available?

stoic cave
# coral token Hey y'all, in the midst of a carer change from banking advisor/sales to cyber se...

Your resume should represent what you did in your professional life. Reading this makes it seem like you're already in Cyber, which from my understanding you're not. Misrepresenting yourself is a very good way to get blacklisted at organizations you're applying to. Your resume should be representive of your professional experience. For you that means documenting what you did as a banking advisor.

faint ice
#

resumes are also supposed to be shorter then a complete CV

stoic cave
obsidian rose
#

I might switch to a new role soon and I have a few questions.

stoic cave
sleek kindle
sleek kindle
#

For me i have 1 year of Work experience in Cybersecurity but i still don’t list a profile section

#

cause until 2 years you are a fresher

#

and a fresher hasn’t actually reeled in any actual results

sleek kindle
sleek kindle
patent current
sleek kindle
#

so i know exactly what you are referring to

#

cause some courses are illegitimate

sleek kindle
patent current
#

Along side websites like TryHackMe, HTB and Boot.dev

#

I like the idea of pen testing, but red or blue not really looked into the benefits / pros and cons of each

sleek kindle
#

and don’t bring any value to your resume

#

but it does give you some knowledge

#

as a beginner

#

try doing the Google Cybersecurity

#

and also Certified in Cybersecurity by ISC2

#

gives you basic knowledge

#

from then on Learn in tryhackme Roadmaps

#

what adds value to your resume is Certifications and Licenses

#

Every Role has different Certifications

patent current
#

Ideal, thats perfect just so i know where to start and once i have these 2 certs could i look at entry level cyber security roles?

sleek kindle
#

So you can ask me for specifics when you decide what you want to do in the field

patent current
#

Perfect thanks mate

patent current
#

Yeah bro

obsidian rose
#

Any Red Team Operator in here?

dreamy mantle
#

Hi guys — long story short: I graduated with a background in networking, spent a year unemployed and didn’t keep learning, which set me back a bit. I’m now in an internship with a task to pentest a small network and write a report. I’m a bit overwhelmed; I’ve been Googling a lot and looking for tips and advice.
(For context: this small company has a little cybersecurity knowledge.)

obsidian rose
# undone shore Hm?

Have you ever encountered a workplace, company or maybe connections with people in companies where Red Team threat intel was a dedicated position?

#

Or is it a very uncommon thing?

undone shore
#

Nah, it's fairly common

obsidian rose
#

And would that person also happen to be an operator or just the intel part?

undone shore
#

Dedicated red teams -- or bigger ones at any rate -- often split their job functions up.
People on R&D, people on ops, people on intel, etc, etc

#

Would depend on the company whether there are overlaps

obsidian rose
#

Ok that's all I needed to know, thanks!

spice stag
dreamy mantle
faint ice
faint ice
#

In English, a curriculum vitae (English: , Latin for 'course of life', often shortened to CV) is a short written summary of a person's career, qualifications, and education. This is the most common usage in British English. In North America, the term résumé (also spelled resume) is used, referring to a short career summary.
The term curriculu...

#

sources if you wanted those

exotic tapir
#

anyone done that CCT cert from ec-council yet?

silk robin
#

So I’ve completed THM’s SOC level 1 path. Any suggestions on what should I do next ? Get the a cloud cert ?

stoic cave
crude burrow
#

You got this

left prairie
#

yo, i m 16 year old, i started hacking 5 years ago (i first used to use termux and all) slowly i learned and now i am doing cyber security from craw.in institute (offline) and i am also doing try hack me and current rank is LEGEND, i have read books such as The hacker playbook 2,3, Practical guide to reverse engeneering, the hackers shellcode and i have doing scripting in python for 2 years and coding in c for 1 year, my course from craw.in is about to end so i am wandering what should i do next, i want to be vulnerability researcher, ------ Need Advices from you all, please help

glossy epoch
real turret
#

Hello

#

I'm back

crude burrow
crude burrow
#

With that amount of knowlage you could get a good job quite easy

#

But it might start wih as a SOC anakyst

#

and move on to vuln analytics

left prairie
crude burrow
junior cliff
#

Is the ejPT cert worth it ?

plush pecan
#

helo

manic phoenix
dreamy mantle
dreamy mantle
serene umbraBOT
#

Gave +1 Rep to @crude burrow (current: #401 - 18)

faint abyss
#

Guys where can i learn HTTP from a cybersecurity expert?

faint abyss
#

Thank you

left prairie
manic phoenix
rigid isle
#

Buy the Cisco CCNA Certification book

#

Check out the CCNA 200-301 class on udemy

#
left prairie
# manic phoenix Any advice ?

depends on what you're struggling with... Every topic need different things so it always depends on context and things its hard to give advice in general

#

at least for me that's the case

manic phoenix
elfin girder
#

Hey has anybody here in the US had any luck with finding entry-level cyber jobs recently? I haven't seen many openings and haven't gotten interviews from anyone I've applied to, and I am straight out of college. I just got my Sec+ and just today got my SAL1.

hollow sierra
#

Not just in usa either, in canada its bad too. big advice i was told was to keep an eye out for jobs that aren't explicitly labeled for cyber but effectively are using cyber skills. for instance an it analyst job that i found for a disability organization that i recently applied for;

elfin girder
#

i wanted a help desk role but those haven't been getting back to me either which sucks because people i know got one, but i guess i'm not good enough...

hollow sierra
#

there's about to be a backlash from managers learning the hard way what happens when the only security people they have are people they have had on payroll for a very long time though;

#

and from them not thinking through the implications of trying to get ai to do a job that literally is only possible by humans because the whole point is that humans are the source of the vulnerabilities;

#

so an llm no matter how well trained is not going to be able to identify the correlations as of yet that indicate someone is trying to bypass security because it can't learn about attacks that haven't happened yet;

elfin girder
#

i've heard a bit about the ai but i thought that was mostly swe. thanks for the advice, i was going to study real hard and take the cysa+ but i guess ill push that off and focus on the ccna and aws saa certs i've been looking into

#

it's kinda sad that college didn't mention any of this before i graduated. i didn't expect to need anything more than sec+ coming out to land an entry level role.

indigo coral
#

anyone hiring aws security consultants/contractors? I'm looking for a side gig of a few months, november-march.

worn zinc
#

Hey guys I was wondering if anybody can give any advice on how to become a security engineer

tranquil carbon
#

Hi everyone, 👋
I’m currently looking for IT/Cybersecurity internship opportunities in the USA, specifically around the DMV area. Would anyone be able to take a look at my resume and give me some feedback? I’d really appreciate it!

elfin girder
quick halo
#

hi guys im a senior in high school right now so i’m getting ready to submit college applications. i feel like my extracurricular activities and supplemental resources are lacking and i’m worried about my chances to get into some good colleges.

right now i’m in a specialized academy within my high school that focuses on programming and i also do some CTFs and produce my own writeups for them on my github. i don’t have many and i want to expand these.

what would look good on my resume / activity list that i could submit in my applications that would let admissions staff know that im dedicated to computer science/cyber security?

tranquil carbon
serene umbraBOT
#

Gave +1 Rep to @elfin girder (current: #3167 - 1)

thorn void
#

.

shadow atlas
#

Guys I am willing to start my career in cybersecurity.where can I learn ,any resources ??

keen tundra
chrome spire
#

Sec+ is a ez cert

#

Entry level

#

Sal1 is unkown by HR

#

You need a IT job or to do projects

#

And mby have someone review your resume

quick halo
# chrome spire Certs

i have a couple of certifications that i acquired through my school, but nothing that sets me apart for cyber security. i feel like i don't know enough right now and i won't be able to learn and study before admissions deadlines

chrome spire
#

And i am sort of in the same boat

chrome spire
#

Like the sec+ and ccna and stuff

#

It proves dedication

#

What certs do you have?

quick halo
arctic arrow
#

Hello! Curious if anyone knows of an upcoming Capture the Flag (beginner friendly)? If you’ve previously completed a CTF, have you found it to be helpful in your career development and/or job search?

vague bough
#

Hi guys, I hope you are all doing well. I’m exploring research areas in cybersecurity that could help me get into a top PhD program and also build a business in the field. Could you suggest which topics are most impactful right now commercially?

chrome spire
#

Those are cool tho

dusty raft
#

I have a question: is it more advantageous to get into a very good university and graduate in the cyber security industry or to go to an average university but get certificates like Security+, OSCP, AWS cloud?

trim tusk
#

the thing is that im trying to find myself an idea for my final year project in cyberSecurity+Ai can you guys suggest something? i have a week only

harsh mirage
#

heya

chrome spire
#

Like i dont get the question

#

If u go to a good univetsity

#

You still need certs

#

But like why not just go if you get in and money isint a issue

#

But if its just for fun you need certs :/

#

No wau around that

dusty raft
# chrome spire Why would you not do both

What I'm trying to say is that the time I'll dedicate to cybersecurity to get into a good university will decrease, and certifications will be delayed. If I'm going to get into a mediocre institution, I'll have plenty of time left to study cybersecurity.

#

Also financial problems, a good university is more expensive

#

But actually you are right, it will just take a little longer but I will get the certificate either way.

chrome spire
#

It will help but I dont think its worth selling your soul and going into debt for

timber sparrow
#

Might be pissing in the wind here...

If somebody built their own cybersecurity homelab complete with SIEM, logging and made a secure home network and all that sort of stuff but had very little IT jobs in the past or certifications, what chance do they stand of getting an entry level SOC job?

fickle grove
timber sparrow
#

thanks 🙂

rugged delta
# timber sparrow thanks 🙂

Having a home lab and being able to discuss in detail what you do with it in an interview really can boost your outcome. Being able to configure/use a SIEM goes a long way in SOC roles, as long as you also know how to use it. Certainly try to replicate intrusions and try to detect them on your own systems, consider making a blog and writing up your findings/activities, and maybe doing writeups of THM rooms. Even summarising your activities for your own notes/learning can go a long way if you don't fancy making detailed notes all the time.

Also, don't hesitate to apply for helpdesk/tech support roles when you're looking for jobs. Also, go to events, meetups, conferences if you have a chance and make connections with organisations there. I'd suggest reading the Tribe of Hackers books. They're a series of interviews with experts for various cyber roles. The author discusses them and his experience in the Darknet Diaries podcast episode 83
https://darknetdiaries.com/episode/83/

lapis crater
#

So in otherwards while you're knocking out certs/practicingTHM/pursing a degree, getting a helpdesk position in mean time is worth while? Also Does having a security clearance help land a SOC like job? @rugged delta

rugged delta
# lapis crater So in otherwards while you're knocking out certs/practicingTHM/pursing a degree,...

Well when you're studying, ideally you'd be spending as much of your time studying as you can. Obviously many people need to earn money to live so perhaps a helpdesk job, even part time might go a long way. If you're doing a degree, for instance, time might be tight for other timesinks, but it really depends on your individual needs and resources. As for having a security clearance helping you land a SOC job, I'm not in the US. There may be benefits to it, but you'd have to discuss that with your potential employers. Also, if you do start somewhere on a helpdesk, this migh open other opportunities internally in that org

elfin girder
#

Some want a polygraph too. I guess the contractors really just don't want to pay for someone to get the required clearance.

#

Shoot 4 years ago I knew someone who got a TS/SCI Help Desk job as a straight civi with only a Sec+ but that doesn't work anymore apparently

dire egret
#

its possible still the military is really looking for Sec+ and experience

#

The military is part of the government, of course, now other gov jobs, I'm not sure.

lapis crater
#

@elfin girder I see thanks for the info, I have a secret, I had no idea there’s government contracting jobs that specifically look for them

serene umbraBOT
#

Gave +1 Rep to @elfin girder (current: #2084 - 2)

elfin girder
dire egret
lapis crater
#

Why they turn you down did they give you any feedback? @elfin girder

elfin girder
#

I’ve applied for a lot of jobs…

dire egret
elfin girder
#

No, still waiting to hear back from an SEL

lapis crater
#

I’ve applied for leidos, trace and booz Allen. We will see what happens

dire egret
#

what certs do you have

lapis crater
#

Non, scheduled my sec plus for December, I have 8 years of military comms/IT experience which is typically what they look for

elfin girder
#

From personal experience, hardest part about Sec+ is the business stuff (BCP, BIA, DRP, etc.)

#

Good luck on that

dire egret
#

u didnt manage to get your TS?

#

or 25U

lapis crater
#

Yes 25B, TS/SCI is in progress, may take a year @dire egret

dire egret
#

ah

#

u still in the army or out

elfin girder
#

Are you guard?

lapis crater
#

Reserves

dire egret
#

were you ever active?

lapis crater
#

Yes for 5 years

elfin girder
#

🫡

dire egret
#

25B is the best MOS

lapis crater
#

Absolutely, tons of opportunities for certs, wish I took them sooner

dire egret
#

I agree I’d say if you want to be an IT guy out of the military it’s your best bet. 17C is more of a hacking mos but they rarely actually hack anything or defend since contractors do it now.

gilded jasper
#

IM SO CONFUSED ABOUT MY CAREER PAth

#

idk what to do with my career path anymore

#

Its either I take AI courses or I take networking courses

#

its either I wanna hack people legally and help them or create an ai for companies

#

I need to find a stable career path for me to earn good money and also enjoy my work..

tropic summit
#

Red team, join us😈

#

Jk

#

Idk im new too but i chose red team

gilded jasper
#

Hacking is fun tho..

tropic summit
#

U might want to choose btw blue or red team or network

gilded jasper
#

and I primarily want to work at a red team

tropic summit
#

Build it or destroy it😈

gilded jasper
tropic summit
#

Nvm

gilded jasper
tropic summit
#

I chose red cuz im want to break things legal way😈

#

And get paid👍

gilded jasper
#

Mostly yeah you wanna get paid

#

but remember the real purpose on why you join the red team

#

its not about the money(YES IT IS BUT)its about helping others

tropic summit
#

Find bugs

#

Ye

gilded jasper
#

AI might not be able to help in complex cases

#

because even if they tried to, they will change one thing and the other codes will get disrupted

#

I think

obtuse prism
dire egret
gilded jasper
#

hands on

dire egret
#

Be a network admin then I find it fun I also find hacking fun but network is fun because you get to actually see and touch the servers physically

graceful quiver
#

Hello all, I have a portfolio question. I'm currently trying to create a SOC Analyst portfolio since that seems to be the best way I can show exp outside of having exp in the work enviroment. I'm planning on trying to use TryHackMe SOC sims for exp and wanted to know is there a good portfolio style or layout to use to show I ihave exp?

junior cliff
#

Guys opinions on pentest + ?

earnest badger
#

Hey, I want a suggestion which burp version is good the latest on or a specific version ( as old is old )

west raft
#

i need flag 16 and flag 17 on windows local persistence >>>? help anyone please

zealous plume
hollow sierra
#

in general avoid certs if a job doesn't require it. and if a job does require a cert, look into job programs that might cover the cost of a cert if you can prove that it would help your career so you can get certified without needing to pay for it;

civic granite
#

Hello, has anyone gone the route of doing volunteer work to gain experience as a SOC?

fickle grove
#

Only big organisations can afford their own SOC because of the required investments and I'm not certain if there would even be internships for it as they are dealing with confidential or sensitive information most of the time. I'm not saying it is zero, but there might be very little opportunity that you will come across.

rugged delta
dark acorn
#

Hey can someone please suggest me vulhub machines, I am most concerned about Windows machine rather than Linux !

stray wolf
#

Can anyone please say what type of projects should I add if I'm a fresher
Applying for
Risk management and compliance role
Please

craggy mountain
finite bison
#

Question. I'm trying to get my Sec+ cert and was wondering if anyone had some study materials that they could recommend? I already know of Professor Messer and a few others as a start but was curious to know if there was anything that someone who has this cert really found useful. Thanks in advance!

elfin girder
#

I mean $10 isn't much compared to the $400 the exam costs + it has a practice test

twilit sparrow
#

👍

cunning shadowBOT
#

:hammer: exhibit_de_hacker#0 has been banned.

daring venture
#

hey guys, im currently pursuing a cs degree and lots of what im taking is AI heavy.
lately i was interested also in cybersec and wanted to ask yall is there like a roadmap on how to begin or which online courses to do? ( there are lots of different yt videos with differing opinions so im lost XD )

im planning on completing msc at my uni so i want something that isnt so time consuming but also can give me solid grounds if i wanna pursue a career that merges both AI and cybersec

thanks for the help 🙌

elfin girder
sonic tartan
chrome spire
remote sun
#

I'm trying to go for cybersecurity or programming positions. I heard that learning SQL and getting certification like Microsoft Azure data fundamentals can help you get one. Maybe just learning SQL and building projects is enough, and I should focus more on the PSAA or the PHDA when it's on sale.

junior adder
#

Any Aussies in here have an opinion on the Certificate IV in Cyber Security?

astral shadow
reef raft
#

Hey guys, been in the web dev industry for the last 10 years but I’ve always had a passion for security. With sec+ and opsec+, would it be difficult to get a role as someone who contributes code within a security context? I don’t want want to stop coding? Even if it’s something like devsecops

mint mason
elfin girder
#

a recruiter recently told me i need a pen test cert for the blue team positions i been applying for

#

for context, i applied to a jr soc l1 analyst position

#

i also already have 2 other certs im studying for - ccna (in place of net+) and cysa+ - like im unemployed and this is expensive 😭

pseudo marten
#

I wanted to ask if anyone knows a path which will teach python coding from scratch with cybersec perspective any tutorial or link

daring venture
daring venture
elfin girder
# daring venture im trying to 😪 , even tho i have some traits ( started bsc at a young age ) my ...

Yeah they're super competitive. I wasn't able to get one. GEs messed up my GPA so for most applications it was < 3.0. The only people I've seen get one had 3.6-4.0 GPAs, were a part of the Cybersecurity (and more) clubs, and had various certifications (aws, sec+, etc.) which i didn't have time or money for then. But those are the same people that landed jobs straight out of college, so it might be worth trying to turn around 🙁

#

Well that and their resumes were extremely good. Like, I didn't know how to make one and I still kind of don't know. Headless Headhunter seems to know his stuff tho on YT so I've been using him as a resource recently

daring venture
mint mason
elfin girder
quaint epoch
tranquil sierra
#

Hi am new here

trail wraith
#

Hey everyone!
I currently work full-time (35 hours a week), and I’m thinking about starting an Open University course next year in cybersecurity — probably something focused on blue teaming. I’ve been offered full funding, so I wouldn’t have to pay for it.
I’m just unsure whether it’s better to go down the Open University route or focus on certifications instead. Has anyone been in a similar situation or have advice on what might be the better option, especially while working full-time?
Thanks in advance!

cunning shadowBOT
#

Done!

hollow sierra
#

just wanted to thank Ben Spring for this lovely article! i don't know if or when i will be able to find a soc analyst job, but if i do this answers pretty much all the questions i've had so far in preparing;

#

if i don't get any luck soon though definetely going to try for sal1 if only just to have something to do besides sending resumes and coverletters to robots in the hopes someday a human actually will read it;

spice plover
#

Looking for a remote jr software developer position if anyone knows of any please think of me thank you!

chrome spire
prime girder
#

rate

#

form 10 points

eternal horizon
#

Hii

#

I need help,I am a beginner

warm hinge
azure sage
#

Anyone got a job for me remote 10 year experience as a system admin trying to go into cyber 2 years experience using Kali Linux / school

junior cliff
#

Anyone can help with IT support job advice in the uk ?

rugged delta
junior cliff
rugged delta
# junior cliff Just need help on how to look struggling to find them etc

You shouldn't limit yourself to just support/helpdesk roles. Look for other IT/cyber roles as well and see what skills they're looking for and if you're able to do most of what they're looking for. Check LinkedIn but also check other recruitment sites and recruiter's offices in your area. It's a competitive environment but keep searching. If there aren't suitable roles in your area, you may need to consider going further afield and/or improving your skills in various ways

mint mason
vital relic
#

whats the general consensus on the sec+

#

any advice or info would be appreciated

mint mason
split briar
split briar
#

Ur welcome broblobfingerguns

undone shore
elfin girder
#

a recruiter for purple/blue team positions told me to go for a pentesting cert so i picked ejpt and am studying for that. was that a bad choice?

cunning shadowBOT
#

:mute: golden_mango_95081#0 has been muted.

split briar
undone shore
silk robin
#

Comptia is coming out with a new cert for AI called: Comptia SecAI plus coming out in 2026. What do you guys think ?

winged scaffold
#

super unnecessary and a cash grab

static bison
#

Hi

split briar
split briar
split briar
silk robin
split briar
young heath
#

Hello everyone , i want some guidance on my current state of my career , i dont know if i have enough knowledge yet , i dont know if i should keep going and when to apply for a job and all this , i was wondering if someone can help me figure this out , idk if i should send my resume here or what XD but here is my thm profile https://tryhackme.com/p/Deku69

#

following up this , i work currently as a technical support engineer and my current goal is to land a job in the cyber security filed , my goal in general is being a red teamer

north bolt
#

Hey guys, I’m new to cybersecurity, so can someone tell me what I should start with first — networking or operating systems?

quaint wren
#

Does anyone recommend any good written/video guides on creating a SIEM homelab

elfin girder
#

I would just use a plain old hypervisor or docker set up for this.

acoustic roost
#

Hi everyone I have a question, idk if I’ve asked this before but, obviously everyone knows that learning everything in cybersecurity is impossible, however, when it comes to pentesting and making it a career at a company, would you recommend being specialized in a certain area? Or be good all around? Or simply be good in one area, and in your free time (if you would like) try exploring different specialized areas

storm frigate
#

Hey everyone, has anyone finshed google cybersecurity course?
I dont know where to focus that course or thm more

static bison
#

I

#

Dont know

quaint wren
serene umbraBOT
#

Gave +1 Rep to @elfin girder (current: #1576 - 3)

quaint wren
#

I have my Ubuntu server setup but the VM performs very slow and it doesn't allow me to enable virtualization

#

I had this issue with my Kali Linux VM but fixed it by just downloading an image online but can't seem to find one for Ubuntu Server

acoustic roost
#

Hi everyone I have a question, idk if I’ve asked this before but, obviously everyone knows that learning everything in cybersecurity is impossible, however, when it comes to pentesting and making it a career at a company, would you recommend being specialized in a certain area? Or be good all around? Or simply be good in one area, and in your free time (if you would like) try exploring different specialized areas

obsidian rose
#

Hard to be a champ at everything, but some solid knowledge in each aspect goes a long way.

acoustic roost
obsidian rose
acoustic roost
#

Obviously not being great at everything

obsidian rose
#

That's a must. Not only that, you must be decent at everything in pentesting.

acoustic roost
obsidian rose
#

Active Directory, Web, OS, Networks...

acoustic roost
obsidian rose
#

Pentesting isn't an entry level position. People usualy do months/years of Help Desk / SOC before getting into it.

#

Very rare are the cases where your first ever job is a pentester.

#

So, at least 6 months to a year of practice, I would say.

#

And that's assuming you aren't competing with people with OSCP who also aren't able to find a job and would most likely be more qualified than someone with no certs.

acoustic roost
#

Ah okokkkk, I get what you mean, you’re saying there’s a higher chance someone would get employment at a company if they are an SOC analyst then transfer to pentesting, rather than a person going straight into pentesting?

obsidian rose
#

Assuming you're someone straight out of school, yes.

acoustic roost
#

Ah okokkkk

obsidian rose
#

If you have OSCP and 3 years of prior experience, that's another story.

acoustic roost
#

Ah okokkk, well thank you so much for your help man😇

acoustic roost
#

Is that true?

obsidian rose
# acoustic roost Is that true?

Yes, but that usually isn't the case for junior positions. Can't really hire an expert in AD as a junior position. A specialist is an expert. Can't be a specialist as a junior with no prior work experience. ¯_(ツ)_/¯

acoustic roost
obsidian rose
#

Logically, yes.

flat sedge
#

Realistically, as a junior you are not going to be decent at anything. If you were decent at any domain, you'd be mid-level at minimum. Junior roles are basically familiar with a small number of domains, but it's expected that they do not have depth of knowledge any where.

dawn veldt
#

Hello everyone. Have a question. Besides going thru the Jr Pentest learning section on Tryhackme, what are some other ways to study for the PenTest+ certification

keen tundra
oblique torrent
#

Hey everyone, I am a mid-level web developer, but I want to learn cybersecurity. I’ve already learned some of the basics of networking and a few Linux terminal commands. My goal is to learn cybersecurity so I can offer it as an add-on service alongside web development.

I’m currently learning through YouTube, but can anyone suggest a good Udemy course or any beginner-friendly course? If there’s a great YouTube channel for beginners, please share your thoughts.
Thanks,
Suffynux

prime quarry
#

hi guys
anyone know about how to do penetration testing for web application

grave needle
#

Portswigger academy.

#

It’s free

sleek kindle
#

I had been trying to get a Job as Security analyst but kept getting rejected for lack of experience

#

so i have been suggested to go into ICS and OT Security

#

Can you guys suggest me if it is a good decision? and any study materials for this field that i can find other than CISA courses

prime quarry
#

even for me also

dawn veldt
tough rapids
#

is there anyone that is a soc analyst i was wondering i have a second interview lined up as a jr soc analyst role and i was just wondering what areas should i focus on and what will they ask and its an emea

jaunty quest
oblique torrent
serene umbraBOT
#

Gave +1 Rep to @jaunty quest (current: #3189 - 1)

sterile gust
#

I will enter university, but I love cyber security. Should I enter computer science as a university major instead of the cyber security college? Because my teacher said that cyber security is a major, not a field. I also believe that cyber security depends on side certificates, a creative major.

elfin girder
vague apex
#

Im looking for a certification related to securing AI programs/data using AI configurations.

Are there any certification recommendations yall have from trustworthy vendors? I found some misc ones online but they are not well-known vendors, or they are certificates for a specific vendor product.

elfin girder
fathom cairn
#

Guys i am struggling to make any money , What can i do ?

ancient gull
#

Best way to get money is by getting a job

#

(So I would apply to some jobs, that you are able to do)

torn narwhal
#

Guys, is a bachelor's degree really required for Helpdesk positions these days?
Especially entry-level and tier 1 support.

elfin girder
#

source: i've been job hunting too 🙁

#

all the government help desk jobs have been asking for bachelor's or master's even for tier 1 and most times also coming in with a ts/sci

next timber
#

Hello there I am a beginner and want to learn cybersecurity can anyone guide me how to start learning?

dusk wedge
still osprey
#

Hey, hope you all are well, I wanted to know if anyone could assist me please, I am busy with an assessment for a learnership for very well known firm here in my country, I managed to succeed from level 0 - level 7 but I have been stuck on Level 8 for the last 5-6 hours

I wanted to know if anyone could assist me, perhaps take a look at it in a call with me provide me with some advice please

cobalt escarp
still osprey
#

Understood, thank you

teal relic
#

Learning TryHackMe rooms and started studying for my CompTia+ whilst working full time

#

Any advice, I watch Proffessor Messer and I am on the Networking Room on TryHackMe

wicked egret
#

Prof messer is great to get foundations that are not convered in thm

lofty pendant
#

Hello Hack the box and try hack me who is the beetter for security engineries??

hollow sierra
#

hack the box and tryhackme are both great tutorial providers. but real hands on experience is always the most valuable in tech;

#

imo tryhackme has the edge because it has the better community and because it uses the tutorials to show examples and then allows you to build your own homelab using those skills you gain from the tutorials to be able to apply the learning towards real goals;

lapis olive
#

Has anyone ever conducted a TLPT?

fringe spade
lapis olive
#

Can you help me the process whichbyou followed? Also what frameworks did you adhere to while conducting TLPT?

fringe spade
lapis olive
fringe spade
lapis olive
#

Yes..okay

lapis olive
hollow sierra
#

For those looking for books, great collection of cyber topics;

rugged delta
stiff oriole
#

Is it okay/normal to ask the recruiter for interview tips? Specifically since I'm going to have a "technical assessment" for my next round, I asked him for tips for the format or what I might expect from it?

hollow sierra
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #18 - 542)

warm hinge
#

Hi coolguy

#

I am new in security world. I want to learn hacking. Any tips???

rugged delta
lament wharf
#

Scammer

daring vapor
#

Does anyone know of ways someone could get unpaid experience as an intern in cybersec?

torpid lantern
#

Yeah

#

Try the virtual internships on theforage

#

They're basically just labs - But you can add them to your LInkedIn

#

That, and if you adjust your CV to include hands-on experience with tools that you've learned while doing THM rooms then you'll look better than someone who just says 'I do THM rooms'

#

If you say like:
Hands-on experience:

  • WireShark
  • Windows Forensics (OSQuery, Autopsy, etc)
  • Wazuh
  • Sentinel
#

Etc

#

If you contribute to open source tools that's a good one too, but for more experience I'd suggest setting up a Wazuh instance on your home network. I have my wazuh running on a laptop under the sofa for instance, and just have agents installed on devices. If you have a proxmox homelab set up that's also something to show off on a CV as experience with tooling for penetration testing and defensive security if you also patch/make SIEM rules for the attacks.

#

@daring vapor

lethal slate
spark sleet
#

Hey,

If this ain’t the right place to ask kindly ping me. So

How is the job market for Digital Forensic in Canada?

#

I asked because after browsing online, it doesn’t seem very specific. So I’m asking to gather some anecdotal data

#

@stoic cave Also if you’re okay with it I’d like your advice on something

torn narwhal
#

@keen tundra or @obsidian rose

#

Crypto scam

gritty zinc
#

I'm new here, does the program get in to web3, blockchain, smart contracts too? I'm not looking to skip my fundamentals, of course, this is just a curiosity when I do get to it some day.

quaint wren
#

Any suggestions for upgrading my first homelab that currently just uses Wazuh for file integrity monitoring of a Windows vm

native steppe
#

I have a question regarding my personal case. Let's say I have no tech background whatsoever, and just about now discovered a passion in the cybersec fields. I've been grinding THM being overly optimistic. Can someone take my head off the clouds and tell me what my real chances are, assuming I study like someone's pointing a Glock at me?

obsidian fjord
#

Continue to grind and grind if you can, and if you have the option, attend a technical school and go for a Compti Security+ certification. The route is different for everyone though. Just know that employers like when you have practical experience and certifications

obsidian fjord
native steppe
#

This is strangely motivating, thank you. I thought I was chasing fairies here. I LOVE the idea of cybersec, but with 0 background on it and forming myself brand new, I'm making some risk assessments before investing too much time in it.

chrome spire
#

Would yal say comp sci or comp eng is better for cybersec (US btw)

rugged delta
# chrome spire Would yal say comp sci or comp eng is better for cybersec (US btw)

Both are very beneficial so you could choose either really. Comp Sci is a very broad topic and you'll cover a lot of similar things in both branches. Comp Eng is really about problem solving, especially for large scale systems. Both will involve plenty of programming, networks, etc and both will be an excellent foundation allowing you to develop the skills and passion you need to develop for cybersecurity

elfin girder
#

There are also cyber security degrees. I got a BS in it

sterile arch
#

i've been contemplating asking this, as a noob XD, so a bit background, (not to bad experienced developer (daily work)), but want to make a career change (as i don't know all the terminology and finding it out now, and started with tryhack me is it possible to build xp do the pt1 and or soc and build some xp in the field (lets say about a 1 of self thought xp) to then start looking at making a career change or will it be better to finish the tryhack me then do like idk CompTIA

chrome spire
keen tundra
fresh crane
#

where should I use go and rust in cybersecurity?

random parrot
#

How hard is the CompTIA sec+? I’ve been studying for about 2 months and I feel like I’m ready to give it a shot

elfin girder
zealous plume
strong scaffold
#

hey everyone
Need advice ! How much time do i need to invest on thm ! , as i am collage student with strict attendence and due to the distance i lost few hours of my day in travelling , i dont hold much on thm , just 2-3 hours and somedays i even skip... what other resouces online best to go parallel with the flow , as i am beginner with good linux command and currently web3 validator ... so yeah good with linux

i am currently learning c and python & bash scripting too ,
do i need to study for the certs or complete some paths on thm then give it a shot!

quaint wren
#

May I send my resume to anyone for review? I'm trying to break into IT/cybersecurity without a degree so I'd like it to be perfect for what I have

rugged delta
# strong scaffold hey everyone Need advice ! How much time do i need to invest on thm ! , as i am...

You should give as much time as you can spare. Obviously you're interested in cybersecurity, but it's understandable it takes a back seat to more prominent things at the moment. Make progress at your own pace. Completing paths should be a goal to help you learn and progress, but don't feel pressured to prioritise it while you're busy with college. Having it as a pastime/extra-curricular is fine at this stage

rugged delta
frigid karma
#

Hello, I was wondering what is the diff between free tryhackme and the prenium one? ( And is it worth to buy it)

crude burrow
# torpid lantern If you contribute to open source tools that's a good one too, but for more exper...

Microsoft Entra, Defender, Senitel - Do the Microsoft trainings for these, there are free labs. No need to get the cert before the workplace pays for it. Just show you have done it and are familiar.

A lot of companies have something with SIEM today and XDR. Learn about this also to put on the resume.

Put something on our github. not that important what it is, just something. @torpid lantern knows what he's talking about.

crude burrow
acoustic skiff
#

I got a degree in html

icy hearth
#

Hello everyone — I'm a final-year student and I'd like to ask for ideas for cybersecurity graduation projects that are easy for a beginner. I know a little Linux and networking, and I'm reasonably willing to learn anything new. I was thinking of creating a honeypot — what do you think, is that a good idea? Give me your opinions and ideas.

stiff oriole
#

Should I bring copies of my resume to an on site interview? Title is “information security engineer”

boreal latch
serene umbraBOT
#

Gave +1 Rep to @boreal latch (current: #3195 - 1)

prime quarry
#

guys how u will be finding the buys in web application
if there any best bug bounty course avalaible

austere turtle
dusk wedge
#

Well, you put your cybersecurity knowledge to work

#

and you try to find some bugs

austere turtle
#

first need course bro😭

prime quarry
#

yes bro

spring kraken
#

career wise, if you're a student should the focus be on learning red teaming concepts more?

#

or should u focus primarily on blue teaming

visual flower
#

Whatever you enjoy more

obsidian rose
#

Not a recruitment server.

wanton arrow
#

hi i would like to do some online courses in my free time to learn more about cybersec, do u have some recommendation?

outer grail
#

whats a good tryhackme room I can complete, preferably challenge, that I can use as an answer in an interview when being asked of a time I displayed skills, looking for a well rounded room

static condor
#

do the quiz of what the ideal pathway is for you

#

and start

tight slate
#

Hi I am a 7 year full stack dev. I am switching to being a Security Engineer. Whats a good learning path, courses and to be able to fully hone in on the skills required to be able to interview for careers with Security Engineering?

#

I know THM has the security engineer path. I’m just wondering if that sufficient enough to hone in on the skills required of Security Engineers.

rugged mesa
#

Then you could ask some AI for example DeepSeek to build a plan for becoming SecEngineer or some skills that required in it

#

There lot of open source info about security engineering in YouTube

#

Have notes of anything that is complicated or undiscovered to you and after a while come back for notes and ask Google or AI to explain it to you shortly enough to remember

#

Wish you all good

tight slate
tight slate
rugged mesa
#

But you can always ask to make answer short enough

tight slate
#

You have any issues with AI Hallucinations?

rugged mesa
tight slate
#

Yea that was the main thing that was deterring me from that path on roadmap.sh. It felt like an overkill for what I was looking for.

rugged mesa
rugged mesa
#

By the time it'll be easy to get

static matrix
#

Hi Folks
Hope you’re doing great

I am pursuing my career as either soc analyst or junior pentester

I recently graduated and worked at the same time as a System, Network & security administrator for 3 years.

Do you have some advice on how to improve my experience and eventually find a job in this field ?

Does anyone have recommendations on Rooms-Labs-CTFs that can actually help me and maybe pass a certification as well ?

I’d really appreciate any advice.
Thank you ! 🙏

#

Please feel free to reach me in DM or here

stone warren
#

I'm currently doing a levels, would ICT be good for cybersecurity and then do an apprenticeship after a levels be good to go down the cybersecurity route?

outer grail
#

anyone have a good source for cyber intern interview questions? specifically pentesting

cedar canyon
#

Using wire shark i captured a web traffic like tcp ,udp , http, https etc
I want too decrypt the encrypted data of website like www.example.com so i search how to do it and i got an ans like use sslkey.log for decrypting the https encrypted data
Its working
Now the qst is there is any other way to get a decrypted data of a https website not http
Does anybody have an idea

edgy orchid
#

Does anyone know of any services like THM for learning how to use Python? I've done some video courses on Youtube but I always learn best by doing hands-on stuff, so something like THM would be really helpful (and preferably, it'd need to be something that's not too expensive, I'm pretty broke from learning at this point and can't even get an interview)

edgy orchid
# keen tundra Codecademy

Oh nice! I think I got Codecademy mixed up with FreeCodeCamp and thought they were primarily a YT channel. Will definitely look into it, thanks!

serene umbraBOT
#

Gave +1 Rep to @keen tundra (current: #1 - 5983)

keen tundra
edgy orchid
# keen tundra Fcc is also great resource btw 🙂

I agree, I've gone through a little bit of their material and it's well-made! I just like hands-on learning when I can get it; I noticed I learned a lot faster in a few months of THM than in almost two years of more traditional learning haha

visual flower
hard crown
#

anyoune here has a career in robotics and can guide me (i am currently in 9th)

hollow pivot
#

Has anyone here done BSCP?

novel nymph
#

Hello all, just had a quick question for anyone.

I am new to the cybersecurity world in the aspect of pursuing it as a career. I have plenty of experience with electronics and usually am the "go-to" person when it comes to technology.

What I'm struggling with is what home labs I should implement in my home. Like what is practical that I could use everyday?

I am working on A+ at the moment but I feel like I should skip that and go straight to net+. I am trying to find an entry level position that will accept me on the Army's Career Skills Program, as I am transitioning out of the military and will be ready to work as an intern come February 2026. Any help/advice is welcome. Please feel free to DM me or reply to this message so I see it.

Thank y'all!

vague mist
#

hello, i need help from someone in india.. i want to pursue cybersecurity as a career and need some guidance.

civic ingot
#

hey i'm looking for a mentor or for someone to help guide me in currently in my second year studying for cybersecurity and forensics BSc and i need helping pushing out stuff that i can fill my CV/resume with to help me get a placement year (year in industry)
im from the UK
any help is appreciated however small or large of advice 🙏🏼🙏🏼

frozen wasp
#

still working through cyber101 path , but was wondering when would be a good time to start focusing on working towards a certificate and what certs should I be looking into isc2 ? comptia certs ?

frozen wasp
potent bear
vague mist
vague mist
potent bear
#

@vague mist okk

weary dawn
jaunty vine
#

Please what is the green word that pop's up

dusk wedge
#

what do you mean?

hollow falcon
#

Stupid(ish) question incoming; what's the rate for a full on penetration test? Like, if a client comes up to you and asks for a pentest on their network infrastructure how much or how would you determine the charge for the work?

#

Does it go by tiers? Like certain tests go for this rate?

fading sage
hollow falcon
#

What would be a range, guess you could say

#

$700? $40,000?

#

$20 lol

fading sage
fading sage
hollow falcon
#

What kind of crazy pentest does the client expect to have them shell out 100K?

#

Would that be like a team engagement situation?

fading sage
hollow falcon
#

So it's a go big and win or lose and go home?

fading sage
#

You're oversimplifying, lol. I'll abstain.

hollow falcon
#

I get what you mean tho

#

Was referring to the part of best of the best

fading sage
hollow falcon
#

It makes sense

fading sage
hollow falcon
#

No

#

I do volunteer bs here and there tho

fading sage
hollow falcon
#

But its not consistent

#

Its like, contracted

fading sage
fading sage
hollow falcon
#

It's both stressful and rewarding

fading sage
#

I think I'm going to refocus my studies on networks. I've been reading Tanenbaum and James Kurose & Keith Ross. Many people around me keep saying, "Study networks, get a solid foundation," and I think I'm falling short in that area...

hazy dagger
#

Iam new too

vague mist
#

ah no issues imma still dm

solid plume
#

Hey everyone! 👋

a final-year Cybersecurity student with only 4 months of study so far. I need guidance for my graduation project but I haven’t decided on an idea yet.

If anyone can give free mentorship, suggest project ideas, or point me to helpful resources/community channels, I’d really appreciate it!

You can reach me here or on imyinsaudi@gmail.com

Thanks a lot!

wanton basin
#

Hi everyone! I’m a second-year student interested in cybersecurity and looking for mentorship or advice on what to learn and focus on. Any guidance on skills, resources, or next steps would mean a lot. Thanks!

simple fern
#

Hi, I’m going to be heading into a university course next year for cyber security and I was hoping to get a head start here, if anyone has any advice on where to start and valuable resources, or things you wish you knew earlier, PLEASE reply or DM me, anything helps ty

dense sorrel
#

Hi all, I'm interested in a career in GRC, can anyone recommend learning paths or rooms.

obsidian rose
#

I've recently been spending a lot of time on Reddit and LinkedIn, and I've noticed quite a few people pivoting directly from SOC roles (mid-tier positions with 2–4 years of experience) or IT manager positions straight into Red Team Operator roles.

Because of that, I've been a bit confused about how this is possible. Maybe these are edge cases, or perhaps I’m just misinformed. Whenever I look at job postings for Red Team Operator positions, they almost always require prior pentesting experience; typically at least three years.

I’ve also heard actual real stories about companies hiring people without prior offensive security experience and training them internally to become RTOs, as long as they already have a background in cybersecurity. (Some even out of college)

So my question is: are these just rare cases of people getting lucky, or are companies genuinely open to hiring candidates without offensive experience and training them to become Red Team Operators? (Yes, I'm aware it's almost the pinnacle of OffSec.)

Obviously, this is a broad question and the answer probably depends on the company, but I’d really appreciate insights from anyone who’s been in the offensive security field for a while. Personally, I haven’t been able to find any company willing to train newcomers in this area. They seem willing to do that for almost every other cybersecurity specialization except offensive security (Training employees for the job in France is required by law).

rugged delta
# obsidian rose I've recently been spending a lot of time on Reddit and LinkedIn, and I've notic...

It does happen that companies pull from internal teams and train up. After leaving a prior cyber post, I heard the pentesting team were recruiting initially internally. A friend of mine was already a QA in another department and I suggested she apply. She got the position and they trained her up.

Usually companies would like someone to have prior IT/cyber experience of several years but some people show potential and are already quite capable in other roles and transitioning a hard worker from one department into pentesting/red teaming is a viable option. Companies can be quite surprising in their hiring practices for various roles

obsidian rose
serene umbraBOT
#

Gave +1 Rep to @rugged delta (current: #18 - 543)

rugged delta
hollow falcon
#

Not sure if joking or being serious

lofty pendant
#

Hi 👋🏾 I would like to become a security engineer I would like you to help me know where I should start or establish a roadmap

hollow falcon
#

Damn, must've been some all-nighters

#

I just get random volunteer "contracts"

#

No pay at all

#

And I do want pay

#

Just being taken advantaged of in hopes of getting my foot in the door.

#

And its a fking federal department

#

And they will randomly call or text me some "mission" they want and Id dedicate a month or two to it

#

Last one was march to early may

#

Been quiet since

#

I kinda like not getting called at 5 in the fking morning

sonic tartan
#

I'd try to look for a more senior position at a new company - get the promo and raise now - you can justify the promo if you have the skillsets the jobs are looking for - just view job reqs on indeed or somewhere for the job title you want

#

i went from desk lead to sysadmin (basically skipped desktop support) back in the day cause I interviewed well and knew my stuff (that was after 2 year degree and 1.5 years on the desk)

#

you could look for a MSSP (managed security services provider) and get tons of experience quick there

#

I'd advise not staying past 2 - 3 years at really any MSP/MSSP to avoid burn out

cosmic cloud
#

Should I get rid of this restaurant work experience if applying to a government computer science job and I have relevant internship experience now?

sonic tartan
#

Do you also have certs or experience on your resume?

#

I think everyone is going to have a different answer here, but if I assume you are fresh out of college with some internship experience, I'd leave the restaurant experience there, especially if you worked those jobs while in college...

it shows you can multi-task, you're committed, you work hard -- I'd update the bullets to include info more relevant to the position

customer service, communication skills, collaboration, any sort of training other employees, etc

#

documentation

zealous plume
#

Depending on the countries you have some vacation days on job anyway so you might use them to deal with burnout short term. First I would talk with SV about possible promotion if it's even possible and change of terms fitting you . Since SOC is burnout generator regardless you gotta somehow deal with that or change role completely for GRC role or consulting. In any case talking to SV should give you enough hints to make a decision

spring swift
#

Hey guys. Would anyone be willing to take a look at my portfolio and CV and tell me what I'm doing wrong? 🥺

#

I haven't gotten any interviews yet, I target apply for specific jobs where I see myself fit instead of spam applying for everything. But still get no feedback for rejection. I want to know what is it that I'm doing wrong.

celest basin
#

hello, would anyone be able to answer what the difference between security co-op job and just security job? please?

sonic tartan
#

you have a job now - it's not your favorite, but it brings in that paycheck - look for the next "dream" position and keep applying

#

I hit 1 year at a position and knew, "this is not for me" - but it wasn't a horrible job - so I looked and applied, I turned quite a few places down because I was picky - now i work 100% wfh and got a 25% bump

vestal vector
#

the issue is that its a 24/7 SOC, the hours are not sustainable

#

it's not about liking it or not, I actually like the team and the workload is relatively low so i have time to study etc., but yeah terrible unsustainable hours

sonic tartan
#

what is your shift? obviously you are not 24/7

vestal vector
#

on top of it, the pay is terrible

sonic tartan
#

that's horrible

#

like.. your employer might as well tell you "you have to smoke an entire pack of cigarettes by the end of your shift" lol

#

you body and brain can't recuperate from a swing shift like that, not that quickly

#

i'd honestly try to show leadership some data on how the human brain/body can't function long term like that...

#

if they don't listen, i'd gtfo asap

#

id rather be homeless

#

lmfao

#

is it a startup?

#

if you are working 5 days a week... they should have 3 shifts...

#

3 or 4 days a week, maybe 2 shifts at 12 hours

#

oh yea, any MSP/MSSP will chew you up and spit you out

#

I worked at an MSP for 4 years - I got TONS of experience but stayed for 1 year too long - I was burnt t F out

vestal vector
#

yup people told me internal SOCs are much better

sonic tartan
#

by the time I left, I was the 23rd person to come and go (meaning I saw 22 new techs from the day I started till the day I quit)

#

we literally were training a new tech every other month lol

#

the company got bought out cause we had a nice datacenter... then the new company dissolved the MSP business and just kept the datacenter business

#

we were bleeding customers so the writing was on the wall

vestal vector
#

the burnout is real and people leave and come all the time

#

definitely more than 2 years here is probably 1 year too much but it was good experience

sonic tartan
#

2-3 years, new job - everytime imo

#

I have several 1.5 - 2 year jobs on my resume and no one questions it

vestal vector
#

do you think they'd question it if it was lower than that? Timewise

sonic tartan
#

I think if you had several <1yr in a row on the resume, yea probably

vestal vector
#

idk though i think it'd be beneficial to just keep interviewing , regardless of getting or accepting an offer , just for the practice and getting better at interviews

sonic tartan
#

if you can explain it too is the key

#

1.5 years service desk - we were contracted by the parent company, they dissolved our contract for budget reasons
1.5 years sysadmin - IT was restructured under the CFO, budgets were slashed, projects halted, looking for more challenges

#

those are my first 2 jobs on my resume and those are true stories

vestal vector
#

are you in blue team now or still sysadmin?

sonic tartan
#

infra engineer - dabble in sysadmin, project management, "blue team" in the sense of hardening systems, escalation for the SOC (you'd send validation/remediation incidents to me depending on your seniority), etc

#

IAM and BCDR too

cosmic cloud
serene umbraBOT
#

Gave +1 Rep to @sonic tartan (current: #1272 - 4)

mint mason
tidal canyon
#

hey guys, do you know during interviews and they ask "how do you keep yourself up to date with current technologies/cyber threats etc", HOW exactly does one stay up to date?

#

not trying to find an answer for interviews, just curious because i do want to stay up to date - job or not.

mint mason
spring swift
#

Here's my CV. Any feedback would be appreciated

#

I don't know if recuiters check portfolios, but I have a projects section in it where I list the work I have done in a summary, then link to blog posts where I go into details of my home lab network.

#

This is my home lab architecture

#

If you were someone working as a blue teamer, and you see my CV and my work, would you be impressed or go like meh?

#

I am open to any criticism and honest thoughts.

#

I think this is better than a PDF file.

dusk wedge
#

I would include a picture of yourself

sonic tartan
sonic tartan
tidal canyon
serene umbraBOT
#

Gave +1 Rep to @sonic tartan (current: #859 - 7)

dusk wedge
#

My school recommends it so that recruits or hr have a face to the person, idk i just always did it since they told us too

sonic tartan
dusk wedge
#

Idk if its like a must

spring swift
sonic tartan
spring swift
tidal canyon
tidal canyon
dusk wedge
#

Yeah i did not consider the discrimination part

#

Thats a good one

tidal canyon
#

but now that i think of it, i think back in asia they did use to recommend having a photo. maybe it really depends on the country/culture

sonic tartan
# spring swift Really? <:cri:631271644287074334>

at one point, I had 3 Dell servers connected to a 50 TB SAN. I had all the computers in my house running on AD but anytime there was an issue, my family was pissed

I realized I didn't want to be fixing IT issues at work 8 hours a day and then being on-call 24/7 for my house stuff too... so it all got recycled or sold

now... my home lab is a dell laptop from 2017 lmfao - it's running a few services when I want to tinker

#

ill spin stuff up in docker, tinker, poke, hack, break, learn and then tear it all back down

spring swift
#

That sounds fun. I pretty much do the same. Most of the setup of my homelab has been in place long before I even started my master's in cyber security. I have been playing around with VPS's since... a very long time so I have always had a place to create a private VPN or just play around with servers.

#

But I just don't know how to translate all this into actual experience that can land me a job lmao

#

I don't think anyone read technical blog posts or projects? Recruiters are the ones that look at it, and I'm like 99% sure they don't understand a thing that is written there.

sonic tartan
#

you are working on a masters in infosec and can't find a job? sheesh the market must be tough

spring swift
#

I finished my master's last year in November XD

sonic tartan
#

your resume(cv) looks good to me BUT

#

do you know how the underlying systems work?

spring swift
#

My German is not good so that limits my options severely

sonic tartan
#

im on the infra side of things and we have some infosec folks who's resumes look like yours and they can barely RDP to a windows box (smh)

spring swift
#

lmao

sonic tartan
#

they can talk the lingo and throw a vuln report in my face, but they couldn't explain the basics of the underlying systems worth a damn

spring swift
#

When you say underlying systems, what do you mean by that?

sonic tartan
#

for example, they'll say "blah blah blah ports need to be blocked 100%" and we will be like, "umm, AD requires these ports to continue to function" and they just stammer... they just stick to their guns "well the report says so"

spring swift
sonic tartan
#

they are rigid infosec - they don't try to understand how things work

#

another example, we migrated from on-prem ADFS SSO to Azure AD
They kept denying our project stating that we "are not allowed to utilize Azure IaaS because the company has not done a security review"

#

Azure AD only shares a name with Azure IaaS

#

we went back and forth for like 6 months

#

they kept asking what Azure firewalls and Azure networks etc we were going to use

#

and we kept having to send them documentation on how Azure AD actually works

#

we basically trained our InfoSec team on Azure AD

spring swift
#

LMAO

sonic tartan
#

don't be one of those people lmfao

spring swift
#

I'm not, I promise.

#

Believe it or not, I had similar situation when I was working as a developer

sonic tartan
#

if I got your resume/cv, I'd put you in the stack to interview, I'd ask you questions specific to our environment to see if you understood the underlying systems too (nothing in depth, but at least you know the basics and such)

#

another example, InfoSec wanted us to block all LDAP traffic midweek and immediately implement LDAPS... like "do it today! right now!"

spring swift
#

I wanted to deploy our webapp on Azure. I pitched the idea to my line manager and he talked to the infosec people and they were outraged. "OUR ON PREMIS SERVERS ARE JUST FINE." This is 4 months after our company was targetted by a ransomware lmao

sonic tartan
#

and we were like, "uhhh, we can work towards that, but we have to get certificates setup from our CAs and reconfigure quite a few parts of the systems"

#

they were like, "NO. It has to be done by the end of the week"

spring swift
#

hahaha XD

sonic tartan
vestal vector
#

also the picture takes a bunch of space and it can be hard sometimes to fit many things in 1 page

spring swift
dusk wedge
#

And contact info

#

Certs and all the other stuff they can find on linkedin

sonic tartan
#

the trick is defense in depth, good backups, immutable backups - lately it's been zero trust networking (micro segmenting every service down to it's own subnet and truly blocking EVERYTHING even internally except for explicitly defined traffic)

spring swift
#

I see

#

If I am running every service/stack in its own docker network on my server, that is considered zero trust as well, right?

sonic tartan
#

somewhat yea, that's part of it

spring swift
#

I know there are dedicated solutions like cloud flare's zero trust, but for my home lab it didn't make sense to implement it. Specially since I already have nginx setup with all the certs etc so redoing all of them would have been a hassle

#

and the only public facing service on my server is my portfolio, which has barely 10 unique users a day if I am lucky

sonic tartan
#

for example, our application servers can only communicate with AD servers, time server - user workstations cannot communicate directly with the app server

spring swift
#

BUT I do get a LOT of directory scans and path traversals that gets blocked at cloudflare

sonic tartan
#

we have zero trust internally too - AD is on VLAN 3, Print Servers are VLAN4, Users VLAN10, App01 on VLAN 101, out of band management on VLAN 102, network gear on VLAN 103, etc etc etc

spring swift
#

That sounds cool, but isn't it a big hassle to manage all that?

sonic tartan
#

its a pain in the ass lmfao

spring swift
#

I can imagine

#

Specially if someone/something needs to access something on the other network, that would be a lot of work, right?

#

or is it easy?

sonic tartan
#

yupp, but that's the point... if its super complicated for us to get someone access to a system, then a threat actor would have a really hard time traversing our network too

#

yupp its a lot of work*

spring swift
#

Makes sense

sonic tartan
#

we have a lot of stuff standardized so it makes more sense

#

just trying not to divulge too too much lol

spring swift
#

I believe it also serves as an excuse to not give john from sales access to something dumb when they request it lmao

#

Because the end user is always asking to run that cracked version of MS word they downloaded

#

or the lottery ticket they won by email

#

XD

sonic tartan
#

yea, end users don't have admin rights. our EDR solution completely blocks all USB mass storage

#

i can't even use a USB drive on my machine either